Different packaging
The package model shipped, defining what blades come with the appliances is divided into xx05(only 2200, 4000 and 61000-series), xx07, xx08 xx10.
The 5-blade package, like 4205, comes with FW, Identity Awareness, VPN, Advanced Networking & Clustering and Mobile access*
And the 7-blade package adds IPS and Application control on top of those again.
The 8-blade package adds DLP
The 10-blade package adds Anti-spam, URL-filtering and AV – But not DLP.

CheckPoint throwing in these blades as “basic” is not surprising as Next Generation Firewalls are defined as a security product integrating Firewall, IPS, Application Control and users & group policies (CheckPoints Identity Awareness) into one product.

* Mobile Access for 5 concurrent users, to allow customer to experiment with the software blade. Note, when you add a CPSB-MOB-50 it will override the pre-installed 5 user-license and support a maximum of 50 concurrent users.

Performance
One of the three main points conveyed by Gil Schwed, was 3x performance boost to the same price as before.
And according to CheckPoints FW/IPS-throughput, SecurityPower, concurrent sessions and port density they have anything from doubled to tripled their numbers while the price is roughly the same.
If the appliances can indeed deliver what they promise – we should be very pleased with the new series.

Hardware redundancy and flexibility
The new appliances, depending on the models, allow you to tailor your appliance into a satisfactory level of performance, port density, port connectivity and redundancy.

Hot-swappable redundant power supplies are optional from the 4800-model and up, and included from the 12400-series and up.

Hard drive redundancy from the 12200-series and up.

Memory
While not mentioned specifically in the presentation, the datasheets reveal that memory can be expanded up to 8 GB for 4800-model and 12 GB for the 12000-series.

Expansion slots and interface cards
All models, except the 2200-series, have expansion slots. There is one slot from 4200 and up to 12200 and three slots from 12400 and up.
These slots can be used to install interface cards, and the following ones are found on CheckPoints website

LOM – Lights out management
From the 4800-series and up, you can acquire Lights out management (CPAC-LOM-INSTALL / $2,500).
This module provides out-of-band remote management for remote diagnostic, remote reboot, installation of OS and so on.

Warranty and support
The appliances and come with one year warranty and you are required to buy support for accessories in addition to the appliance itself.

Operating system
The appliances run SPLAT R75, but is optimized for Gaia. So running Gaia on the appliances when it goes GA in 2012 should not be an issue. =)

I’m happy with this new release as CheckPoint, and certainly that they are taking a step closer to releasing only NGFWs. And that without increasing the price significantly.
And hopefully the appliances can deliver what CheckPoint promise.